First published: Wed Sep 01 2021(Updated: )
OpenEMR 6.0.0 has a pnotes_print.php?noteid= Insecure Direct Object Reference vulnerability via which an attacker can read the messages of all users.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Open-emr Openemr | =6.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-40352 is an Insecure Direct Object Reference vulnerability in OpenEMR 6.0.0.
CVE-2021-40352 has a severity rating of 6.5 (medium).
CVE-2021-40352 allows an attacker to read the messages of all users in OpenEMR 6.0.0.
To fix the CVE-2021-40352 vulnerability, you should apply the recommended security patches or updates provided by OpenEMR.
You can find more information about CVE-2021-40352 on the official OpenEMR website, as well as the provided references.